MICROSOFT CORPORATION
ent_dd164435fc3308ca23261a93
Disclosures
6
Leak Site · State AG · SEC 8-K · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
147
as filed · State AG MA
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- MICROSOFT CORPORATION
- Normalized
- microsoft— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- INR2EJN1ERAN0W5ZP974
- SEC EDGAR CIK
- 0000789019
- Domain
- microsoft.com
Disclosure history (6)newest first
- GLOBALLeak Siteas victim2026-07-26
Revenue: $318B DATA SUMMARY: 8M~ records containing: significant PII, employee and customer contact information, authentication data, password hashes, portal identities, corporate account information, business leads, facilities management records, internal service tickets, and access permissions.
- Massachusetts State AGas reporting2025-06-04
Clarity Group (“Clarity”) reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-06-04. 4 Massachusetts residents were affected.
- FEDERALSEC 8-Kas victim2024-03-08
Microsoft filed an 8-K/A amending its January 19, 2024 disclosure of a cybersecurity incident attributed to nation-state threat actor Midnight Blizzard. Beginning in late November 2023, the actor accessed and exfiltrated information from a small percentage of corporate email accounts, including senior leadership, cybersecurity, and legal personnel. Microsoft has since determined the actor used that information to attempt unauthorized access to source code repositories and internal systems. Investigation remains active.
- FEDERALSEC 8-Kas victim2024-01-19
Microsoft disclosed via SEC Form 8-K Item 1.05 that on January 12, 2024 it detected a nation-state associated threat actor (Midnight Blizzard) had, beginning in late November 2023, gained access to and exfiltrated information from a very small percentage of employee email accounts, including senior leadership and staff in cybersecurity and legal functions. Access was removed on or about January 13, 2024. The incident had no material operational impact as of the filing date.
- Massachusetts State AGas reporting2020-02-24
Apps Associates Holdings, LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-02-24. 147 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas reporting2018-07-20
Connect Your Care LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-07-20. 12 Massachusetts residents were affected. The report records the breach type as electronic.
Subsidiary disclosures (3)filed by group companies
◈ These filings were made by or about subsidiaries of MICROSOFT CORPORATION — not by MICROSOFT CORPORATION itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- GLOBALPressvia GITHUB INC2026-05-19
GitHub, 3,800 internal repositories stolen incident investigation launched (GITHUB, VS Code, malicious extension, cyberattack). GitHub: On May 20, GitHub published the results of its investigation into an intrusion into its internal repositories, resulting from an attack conducted using a malicious Visual Studio Code (VS Code) extension. This attack targeted an employee's devices the day before, and GitHub took measures to remove the malicious version of the extension and isolate the affected terminals. The investigation revealed that approximately 3,800 repositories had been compromised, matching the scale claimed by the attacker, TeamPCP. To mitigate security risks, GitHub rotated critical security keys starting on May 19 and plans to continue analyzing system logs and monitoring in the future.
- Massachusetts State AGvia ACTIVISION PUBLISHING, INC.2017-08-16
Activision Publishing, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-08-16. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGvia LinkedIn Corporation2016-06-02
LinkedIn Corporation notified the California Attorney General that data stolen in a 2012 breach was being made available online. On May 17, 2016, LinkedIn became aware of the exposure. The compromised data included member email addresses, hashed passwords, and LinkedIn member IDs. LinkedIn invalidated passwords for affected accounts created prior to 2012 that had not been reset. The company engaged law enforcement and implemented security enhancements including salted password hashing and two-step verification options.